• Resolved spherical

    (@spherical)


    It has occurred to me that the Admin Login notices sent to our verified email addresses contain the full username used. Administrators do not really need the full string in order to verify that the string is valid. We know what our usernames are.

    I would respectfully suggest that at least half of the username string be obfuscated. If anyone out there can successfully intercept an email, especially one coming from WordFence, they have now been afforded a username in full that DOES Work.

    Please give this a serious consideration. Thank You!

    • This topic was modified 17 hours, 22 minutes ago by spherical.
Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter spherical

    (@spherical)

    Evidently my edit didn’t get processed… So I’ll try again this way to get this completed.

    Additionally, I would strongly suggest that, if a WordFence user has whitelisted their IP# that they be given the opportunity to suppress or obfuscate it in said eMail notices. Admins know what our valid data is and can recognize same from partials. No real need to disclose sensitive data in repeated notices.

    Great product, by the way. Since installing, my eMail has exploded with cracking attempts notices. Some of the usernames tried are really dumb. Others are gleaned from visible strings on the blog and, if an Admin is smart, they won’t use anything remotely similar as a username. If they do, they deserve to be cracked.

    Plugin Support wfphil

    (@wfphil)

    Hi @spherical

    I have passed your feedback and feature request to the team for you.

    All feature requests are discussed by the team and given careful consideration.

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.